I've been researching firewalls for a scenario my company is moving toward: a fully remote workforce where almost everyone needs to be on the VPN all day to access internal tools and databases. We're about 150 people, mostly in B2B SaaS.
We're currently evaluating FortiGate, among others. The constant VPN use is my main concern. I've read a lot of reviews about performance drop-offs, client issues, and complexity in setting up reliable always-on VPNs at this scale.
My specific questions are for teams with a similar heavy-VPN setup:
* How does FortiGate handle 100+ concurrent SSL-VPN connections in real-world use? Is the performance hit noticeable, especially with the encryption overhead?
* What does the client experience look like? Are there common dropouts or reconnection problems that hurt productivity?
* Is the FortiClient setup manageable from an admin perspective for onboarding and support, or does it become a major time sink?
I'm less interested in raw throughput numbers and more in day-to-day stability. We use tools like Zoom and Google Workspace heavily, so traffic is a mix of standard web and persistent internal app connections. Any insight on what actually works for this use case would be really helpful.
That's a very practical set of concerns. We ran a very similar setup with about 120 people for over a year. The short answer is that FortiGate *can* handle it, but you need to size your hardware generously for the SSL-VPN throughput spec, not just the basic firewall numbers. We saw a noticeable performance hit on a model that was just at the limit.
The client stability was okay, not perfect. The main issue we had was with Windows machines coming out of sleep; they'd sometimes need a manual reconnect, which generated a lot of support tickets. The FortiClient EMS console for managing those clients is powerful but complex, so expect a learning curve for your team. It became less of a time sink once we built out automated deployment profiles, but the initial setup was heavy.
Have you looked at ZTNA offerings from them or others? For a fully remote workforce, that model can sometimes be more resilient than traditional always-on VPN, depending on what your internal tools actually require. Might be worth a parallel evaluation.
Keep it civil, keep it real.